Preventing sensitive content specifically — such as financial information — from being uploaded to a generative AI application requires content-aware inspection capable of recognizing patterns like account numbers, financial statement data, or other regulated data types within the actual payload of the upload, which is precisely the function Enterprise DLP is designed to perform. AI Access Security integrates with Enterprise DLP so that an administrator can build a rule targeting the data patterns that constitute " financial information, " and apply it specifically to traffic destined for sanctioned or monitored generative AI applications like ChatGPT, blocking the upload at the content level regardless of the file format or transport mechanism used. This makes Enterprise DLP the correct complementary control to a Security policy, and option B the correct answer. File Blocking (option A) operates on file type and extension, not on the semantic content of a file or a text-based upload — it cannot selectively identify " financial information " within an otherwise permitted file type, so it is not a content-aware control suited to this requirement. URL Filtering (option C) governs access to categorized websites and can restrict or allow entire domains, but it has no capability to inspect the content of an upload for sensitive data patterns; it is a destination-control mechanism, not a data-loss-prevention mechanism. A vulnerability profile (option D) is designed to detect exploitation attempts against known software vulnerabilities, which is entirely unrelated to inspecting outbound user-submitted content for sensitive data.
[Reference:AI Access Security – Enterprise DLP Integration for Generative AI Data Protection.]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit